๐บ๐ธ
TPI-Abuse
2024-03-05 23:44:18
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknow ...
show more
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 05 18:44:11.065132 2024] [security2:error] [pid 32262] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e:51340] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.solarfarms.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.solarfarms.info"] [uri "/wp-json/wp/v2/users"] [unique_id "ZeeuS5_Cx5yU2vV2H-CZ9QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-05 19:51:03
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknow ...
show more
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 05 14:51:00.136101 2024] [security2:error] [pid 27566] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e:58616] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||suefellows.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "suefellows.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Zed3pBJHuS6bNsRDuJEmmwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-05 17:42:44
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknow ...
show more
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 05 12:42:36.771188 2024] [security2:error] [pid 19262] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e:37376] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||peterjohnsonauthor.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "peterjohnsonauthor.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZedZjD9h4iP9AiaBUeukdAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-05 16:11:55
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknow ...
show more
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 05 11:11:49.308571 2024] [security2:error] [pid 3176] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e:45704] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tapwagon305.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tapwagon305.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZedERa1XsjW2I3v0QlUxswAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-05 14:13:43
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknow ...
show more
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 05 09:13:40.122310 2024] [security2:error] [pid 32599] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e:38814] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||greatchristianadventure.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "greatchristianadventure.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZecolFx0BMx8M1m2Md94BQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
karger
2024-03-05 09:09:24
(2 years ago)
Wordpress attack - hard filter
Brute-Force
Web App Attack
๐ธ๐ช
maxxsense
2024-03-05 08:37:02
(2 years ago)
(wordpress) Failed wordpress login from 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (US/United States/-)
Brute-Force
๐ฉ๐ช
SpaceHost-Server
2024-03-05 07:05:16
(2 years ago)
2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e - - [05/Mar/2024:08:04:59 +0100] "POST /wp-login.php HTTP/1. ...
show more
2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e - - [05/Mar/2024:08:04:59 +0100] "POST /wp-login.php HTTP/1.1" 200 11451 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e - - [05/Mar/2024:08:05:00 +0100] "POST /xmlrpc.php HTTP/1.1" 200 1141 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e - - [05/Mar/2024:08:05:15 +0100] "POST /wp-login.php HTTP/1.1" 200 9793 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-04 09:20:31
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknow ...
show more
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 04 04:20:25.919638 2024] [security2:error] [pid 29162] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e:54692] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.orcastrong.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.orcastrong.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZeWSWca-JhO3VmZYbYH_LwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2024-03-04 08:09:14
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-03-04 07:35:25
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknow ...
show more
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 04 02:35:19.157987 2024] [security2:error] [pid 16758] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e:53618] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||indyham.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "indyham.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZeV5t5zuQBt6D0dQB3uoeQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-04 07:10:13
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknow ...
show more
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 04 02:10:06.912679 2024] [security2:error] [pid 564107] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e:56772] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gazelleplanner.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gazelleplanner.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZeVzzr5hJ2_u7eK4mgwoFwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-04 06:32:12
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknow ...
show more
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 04 01:32:06.588994 2024] [security2:error] [pid 19104] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e:36912] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.nickwhittleton.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.nickwhittleton.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZeVq5hL4c_16_uaFZLmSqQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-03-03 07:47:07
(2 years ago)
www.handydirektreparatur.de 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e [03/Mar/2024:08:47:06 +0100] "PO ...
show more
www.handydirektreparatur.de 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e [03/Mar/2024:08:47:06 +0100] "POST /wp-login.php HTTP/1.1" 200 6778 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
www.handydirektreparatur.de 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e [03/Mar/2024:08:47:07 +0100] "POST /xmlrpc.php HTTP/1.1" 200 4110 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-29 18:18:39
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknow ...
show more
(mod_security) mod_security (id:225170) triggered by 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 29 13:18:32.492599 2024] [security2:error] [pid 12147] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e:50724] [client 2600:1f16:1a2e:a300:b0f4:ea2e:2242:c86e] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.usaangelinvestors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.usaangelinvestors.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZeDKeKVWRq4c7PD2x2Rf2QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack